Now Building

Enterprise Homelab Progress

Public progress tracker for the ElliottSecurity Enterprise Homelab — milestones, roadmap, and what is being built now.

Current Milestone

DCP-005

Current Phase

Monitoring

Next Milestone

DCP-006

Next Objective

Expand Elastic storage configuration; broaden endpoint telemetry; validate first detections

Last updated: August 26, 2026

Current Focus

Homelab workloads continue migrating into role-specific network segments. Security, analysis, development, lab, and identity systems were remapped and validated after infrastructure changes. Internal name resolution was updated, a hardened firewall policy was implemented, and Elastic storage capacity was expanded. Remaining work includes finishing Elastic storage configuration, broadening agent coverage, and validating detections.

Timeline

  1. 2026-08-26DCP-005 — segmented workload migration, DNS updates, firewall hardening, Elastic storage expansion
  2. 2026-08-09DCP-005 — HTB analysis VMs, storage expansion, VLAN segmentation started
  3. 2026-08-06DCP-005 — observability hardening, threat intel, partial snapshots
  4. 2026-08-03DCP-005 in progress — ELK/Fleet telemetry, lab & analysis workloads, AD OU model
  5. 2026-08-03DCP-004 completed — golden templates including REMnux
  6. 2026-07-29DCP-004 — Windows and Linux golden templates converted
  7. 2026-07-27DCP-003 — AD, DNS, DHCP, WireGuard, management networking
  8. 2026-07-20DCP-002 — OPNsense, WiFi bridge, Proxmox networking
  9. 2026-07-19DCP-001 completed — Proxmox foundation
  10. TBDDCP-006 — Detection engineering loop

Progress Indicators

  • WiFi BridgeComplete
  • OPNsenseComplete
  • Internal NetworkingComplete
  • Network SegmentationIn Progress
  • Infrastructure FoundationComplete
  • Active DirectoryComplete
  • DNSComplete
  • DHCPComplete
  • WireGuard VPNComplete
  • Golden TemplatesComplete
  • Elastic / MonitoringIn Progress
  • Analysis WorkloadsIn Progress

Completed Milestones

  1. DCP-0012026-07-19

    Proxmox Foundation

    Installed and hardened Proxmox VE, created backup administrator accounts, disabled root GUI login, and established enterprise VM pools.

  2. DCP-0022026-07-20

    Networking & Edge Foundation

    Built the WiFi edge bridge, installed OPNsense, configured Proxmox bridges, uploaded ISOs, and created the Domain Controller VM shell.

  3. DCP-0032026-07-27

    Identity & Remote Access Baseline

    Deployed Active Directory, DNS, and DHCP on Windows Server 2025; completed OPNsense routing and WireGuard VPN; improved Proxmox management networking.

  4. DCP-0042026-08-03

    Golden Templates / Telemetry Prep

    Built reusable Windows and Linux golden images, including REMnux template infrastructure, for consistent lab deployments.

Upcoming Milestones

  1. DCP-005

    Telemetry Platform

    Operate and harden Elastic Stack and Fleet, migrate workloads into role-specific segments, expand analysis capacity, and prepare detection validation. Status: In Progress (~80%).

  2. DCP-006

    Detection Engineering Loop

    Validate first detections end-to-end against lab telemetry.

Infrastructure Inventory

  • Edge Bridge

    Active

    WiFi-to-Ethernet edge bridge

    Upstream connectivity path for the Proxmox host and lab edge.

  • Lab Firewall

    Operational

    Firewall, router, and VPN gateway

    Edge security boundary with hardened policy and verified remote access.

  • Domain Controller

    Operational

    Active Directory, DNS, and DHCP

    Identity plane with organizational-unit foundations and updated name resolution.

  • Golden Templates

    Complete

    Standardized lab OS images

    Windows, Ubuntu, Kali, and REMnux templates migrated to expanded storage.

  • Security Monitoring

    In Progress

    Elastic Stack and Fleet

    Hardened internal platform with expanded storage capacity and validated web access after network changes.

  • Lab & Analysis Workloads

    Deployed

    Endpoint, offensive, and malware-analysis systems

    Windows lab endpoint, Kali lab guest, REMnux, and dedicated HTB/DFIR analysis guests online in segmented networks.

  • Development Automation

    Deployed

    AI-assisted development host

    Development VM online on the development segment.

Architecture Overview

Live architecture: Internet to home router to WiFi edge bridge into Proxmox. The lab firewall provides routing, hardened policy, and VPN remote access. Active Directory supplies identity, DNS, and DHCP. Golden templates accelerate guest builds. An internal Elastic Stack with Fleet collects endpoint telemetry, with threat-intelligence enrichment and expanded storage capacity. Workloads are migrating into role-specific network segments for identity, security, analysis, development, and lab use. Detection validation remains open.

Roadmap

  • Foundation

    complete

    100%

    • Proxmox VE hardened and managed on the lab network
    • Enterprise VM pools and ISO library
    • Golden OS templates complete
  • Infrastructure

    in progress

    78%

    • Domain Controller operational
    • Lab, analysis, development, and security workloads deployed
    • Backup job cadence (remaining)
  • Networking

    in progress

    85%

    • OPNsense edge firewall and routing
    • Internal lab network
    • WireGuard remote access
    • Role-specific segmentation advanced (validation remaining)
  • Security

    in progress

    75%

    • Active Directory domain and OU foundations
    • DNS and DHCP on the domain controller
    • Hardened firewall policy implemented
    • GPO baselines and AD CS (remaining)
  • Monitoring

    in progress

    80%

    • Elastic Stack online for internal monitoring
    • Observability and Security validated for a Windows lab endpoint
    • Threat-intelligence feed and auditing enabled
    • Expanded Elastic storage capacity (configuration remaining)
    • Expanded agent coverage (remaining)
  • Detection Engineering

    planned

    5%

    • Detection-as-code workflow
    • Validation against live Sysmon telemetry
  • Threat Hunting

    planned

    0%

    • Hunt hypotheses and case studies
  • Automation

    planned

    20%

    • Status sync automation
    • Golden-image maintainability patterns
    • AI development host online
  • Portfolio

    in progress

    58%

    • Lab Progress sync
    • Public infrastructure narrative
    • Progress writeups

Recent Changes

  • 2026-08-26DCP-005 — Segmented workload migration and reliability

    Migrated security, analysis, development, lab, and identity workloads into role-specific network segments; updated internal name resolution including reverse zones; implemented a hardened firewall policy; expanded Elastic storage capacity; and validated service availability after the changes.

  • 2026-08-09DCP-005 — Analysis expansion and segmentation

    Added dedicated Windows and Linux analysis environments for authorized lab work, installed additional virtualization storage and migrated golden templates, and began network segmentation.

  • 2026-08-06DCP-005 — Observability hardening and reliability

    Hardened the Elastic monitoring platform, added threat-intelligence enrichment, validated endpoint observability after time-sync remediation, and captured known-good snapshots for critical monitoring and edge systems.

  • 2026-08-03DCP-005 — Telemetry platform and lab workloads

    Advanced Active Directory organizational foundations, deployed Windows and Kali lab endpoints, stood up REMnux analysis capacity, and brought an internal Elastic Stack online with Fleet-based Sysmon telemetry from a domain-joined workstation.

Recently Completed

  • Migrated applicable workloads into role-specific network segments
  • Updated internal DNS and reverse lookup coverage for segmented networks
  • Implemented hardened firewall policy and expanded remote-access reachability
  • Expanded Elastic storage capacity
  • Validated service availability after infrastructure changes
  • Expanded Windows and Linux analysis capacity for lab and DFIR practice
  • Installed additional virtualization storage and migrated golden templates
  • Hardened Elastic monitoring accounts, keys, and break-glass practices
  • Enabled Elasticsearch auditing and system-log data views
  • Added AlienVault OTX threat-intelligence feed
  • Validated Windows lab endpoint visibility in Observability and Security
  • Established Active Directory organizational-unit foundations

Evidence & Diagrams

Screenshots

Screenshots pending for Elastic Fleet status and AD OU evidence (redacted).

Architecture Diagram

Architecture diagram placeholder — high-level Mermaid overview below; static export assets TBD.

Build Narrative

Enterprise Homelab Progress

The ElliottSecurity Enterprise Homelab runs on Proxmox VE with an OPNsense edge firewall, identity services, reusable golden images, and an internal Elastic Stack. DCP-005 is in progress: segmented networking advanced on 2026-08-26 with migrated workloads, updated name resolution, firewall hardening, and expanded Elastic capacity. Detection validation and broader telemetry coverage remain open.

Current Focus

Homelab workloads continue migrating into role-specific network segments. Security, analysis, development, lab, and identity systems were remapped and validated after infrastructure changes. Internal name resolution was updated, a hardened firewall policy was implemented, and Elastic storage capacity was expanded. Remaining work includes finishing Elastic storage configuration, broadening agent coverage, and validating detections.

Progress Indicators

  • WiFi Bridge — complete
  • OPNsense — complete
  • Internal Networking — complete
  • Network Segmentation — in progress
  • Infrastructure Foundation — complete
  • Active Directory — complete
  • DNS — complete
  • DHCP — complete
  • WireGuard VPN — complete
  • Golden Templates — complete
  • Elastic / Monitoring — in progress
  • Analysis Workloads — in progress

Timeline

  • 2026-08-26 — DCP-005 — segmented workload migration, DNS updates, firewall hardening, Elastic storage expansion
  • 2026-08-09 — DCP-005 — HTB analysis VMs, storage expansion, VLAN segmentation started
  • 2026-08-06 — DCP-005 — observability hardening, threat intel, partial snapshots
  • 2026-08-03 — DCP-005 in progress — ELK/Fleet telemetry, lab & analysis workloads, AD OU model
  • 2026-08-03 — DCP-004 completed — golden templates including REMnux
  • 2026-07-29 — DCP-004 — Windows and Linux golden templates converted
  • 2026-07-27 — DCP-003 — AD, DNS, DHCP, WireGuard, management networking
  • 2026-07-20 — DCP-002 — OPNsense, WiFi bridge, Proxmox networking
  • 2026-07-19 — DCP-001 completed — Proxmox foundation
  • TBD — DCP-006 — Detection engineering loop

Completed Milestones

  • DCP-001 — Proxmox Foundation (2026-07-19): Installed and hardened Proxmox VE, created backup administrator accounts, disabled root GUI login, and established enterprise VM pools.
  • DCP-002 — Networking & Edge Foundation (2026-07-20): Built the WiFi edge bridge, installed OPNsense, configured Proxmox bridges, uploaded ISOs, and created the Domain Controller VM shell.
  • DCP-003 — Identity & Remote Access Baseline (2026-07-27): Deployed Active Directory, DNS, and DHCP on Windows Server 2025; completed OPNsense routing and WireGuard VPN; improved Proxmox management networking.
  • DCP-004 — Golden Templates / Telemetry Prep (2026-08-03): Built reusable Windows and Linux golden images, including REMnux template infrastructure, for consistent lab deployments.

Upcoming Milestones

  • DCP-005 — Telemetry Platform: Operate and harden Elastic Stack and Fleet, migrate workloads into role-specific segments, expand analysis capacity, and prepare detection validation. Status: In Progress (~80%).
  • DCP-006 — Detection Engineering Loop: Validate first detections end-to-end against lab telemetry.

Infrastructure Inventory

  • Edge Bridge (Active): Upstream connectivity path for the Proxmox host and lab edge.
  • Lab Firewall (Operational): Edge security boundary with hardened policy and verified remote access.
  • Domain Controller (Operational): Identity plane with organizational-unit foundations and updated name resolution.
  • Golden Templates (Complete): Windows, Ubuntu, Kali, and REMnux templates migrated to expanded storage.
  • Security Monitoring (In Progress): Hardened internal platform with expanded storage capacity and validated web access after network changes.
  • Lab & Analysis Workloads (Deployed): Windows lab endpoint, Kali lab guest, REMnux, and dedicated HTB/DFIR analysis guests online in segmented networks.
  • Development Automation (Deployed): Development VM online on the development segment.

Architecture Overview

Live architecture: Internet to home router to WiFi edge bridge into Proxmox. The lab firewall provides routing, hardened policy, and VPN remote access. Active Directory supplies identity, DNS, and DHCP. Golden templates accelerate guest builds. An internal Elastic Stack with Fleet collects endpoint telemetry, with threat-intelligence enrichment and expanded storage capacity. Workloads are migrating into role-specific network segments for identity, security, analysis, development, and lab use. Detection validation remains open.

Roadmap

Foundation

  • Status: complete

  • Progress: 100%

    • Proxmox VE hardened and managed on the lab network
    • Enterprise VM pools and ISO library
    • Golden OS templates complete

Infrastructure

  • Status: in-progress

  • Progress: 78%

    • Domain Controller operational
    • Lab, analysis, development, and security workloads deployed
    • Backup job cadence (remaining)

Networking

  • Status: in-progress

  • Progress: 85%

    • OPNsense edge firewall and routing
    • Internal lab network
    • WireGuard remote access
    • Role-specific segmentation advanced (validation remaining)

Security

  • Status: in-progress

  • Progress: 75%

    • Active Directory domain and OU foundations
    • DNS and DHCP on the domain controller
    • Hardened firewall policy implemented
    • GPO baselines and AD CS (remaining)

Monitoring

  • Status: in-progress

  • Progress: 80%

    • Elastic Stack online for internal monitoring
    • Observability and Security validated for a Windows lab endpoint
    • Threat-intelligence feed and auditing enabled
    • Expanded Elastic storage capacity (configuration remaining)
    • Expanded agent coverage (remaining)

Detection Engineering

  • Status: planned

  • Progress: 5%

    • Detection-as-code workflow
    • Validation against live Sysmon telemetry

Threat Hunting

  • Status: planned

  • Progress: 0%

    • Hunt hypotheses and case studies

Automation

  • Status: planned

  • Progress: 20%

    • Status sync automation
    • Golden-image maintainability patterns
    • AI development host online

Portfolio

  • Status: in-progress

  • Progress: 58%

    • Lab Progress sync
    • Public infrastructure narrative
    • Progress writeups

Recent Changes

  • 2026-08-26 — DCP-005 — Segmented workload migration and reliability: Migrated security, analysis, development, lab, and identity workloads into role-specific network segments; updated internal name resolution including reverse zones; implemented a hardened firewall policy; expanded Elastic storage capacity; and validated service availability after the changes.
  • 2026-08-09 — DCP-005 — Analysis expansion and segmentation: Added dedicated Windows and Linux analysis environments for authorized lab work, installed additional virtualization storage and migrated golden templates, and began network segmentation.
  • 2026-08-06 — DCP-005 — Observability hardening and reliability: Hardened the Elastic monitoring platform, added threat-intelligence enrichment, validated endpoint observability after time-sync remediation, and captured known-good snapshots for critical monitoring and edge systems.
  • 2026-08-03 — DCP-005 — Telemetry platform and lab workloads: Advanced Active Directory organizational foundations, deployed Windows and Kali lab endpoints, stood up REMnux analysis capacity, and brought an internal Elastic Stack online with Fleet-based Sysmon telemetry from a domain-joined workstation.

Recently Completed

  • Migrated applicable workloads into role-specific network segments
  • Updated internal DNS and reverse lookup coverage for segmented networks
  • Implemented hardened firewall policy and expanded remote-access reachability
  • Expanded Elastic storage capacity
  • Validated service availability after infrastructure changes
  • Expanded Windows and Linux analysis capacity for lab and DFIR practice
  • Installed additional virtualization storage and migrated golden templates
  • Hardened Elastic monitoring accounts, keys, and break-glass practices
  • Enabled Elasticsearch auditing and system-log data views
  • Added AlienVault OTX threat-intelligence feed
  • Validated Windows lab endpoint visibility in Observability and Security
  • Established Active Directory organizational-unit foundations

Screenshots Placeholder

Screenshots pending for Elastic Fleet status and AD OU evidence (redacted).

Architecture Diagram Placeholder

Architecture diagram placeholder — high-level Mermaid overview below; static export assets TBD.

Mermaid Diagram Placeholder

flowchart TB
  Internet((Internet)) --> HomeRouter[Home Router]
  HomeRouter --> EDGE["Edge Bridge"]
  EDGE --> PX["Proxmox Host"]
  Remote["Remote clients"] -->|VPN| FW
  PX --> FW["Lab Firewall / Router / VPN"]
  FW --> EDGE
  PX --> ID["Identity · DNS · DHCP"]
  PX --> MON["Elastic Stack / Fleet"]
  PX --> LAB["Lab & Analysis Workloads"]
  PX --> DEV["Development / Automation"]
  LAB -->|"Endpoint telemetry"| MON